Concepts
Floating IPs and firewalls
Public IPv4 addresses you can move between servers in about a second, and per-server stateful firewalls for IPv4 and IPv6.
Floating IPs#
A floating IP is a public IPv4 address held by your account and forwarded 1:1, inbound and outbound, to a server. Moving it to another server takes effect within about a second, which makes it the simplest way to fail a service over or to keep an address across a rebuild.
ankra-cloud floating-ips allocate --zone de-fsn1 --server <server-id> --wait
ankra-cloud floating-ips assign <floating-ip-id> --server <other-server-id> --wait
ankra-cloud floating-ips release <floating-ip-id> --wait
A floating IP's target says where it forwards:
public(the default): the server's public interface.private:<network_id>: the server's interface on that private network, which must be attached to a router with NAT enabled. The address then enters and leaves through that NAT gateway, so an IPv6-only server can still own a public IPv4.
While a floating IP forwards to a private interface, turning off that router's NAT, detaching the network from the router or detaching the server from the network answers 409; unassign the floating IP first.
Allocating with a server_id checks the target first and allocates and assigns in one step, so a refused assignment
keeps no address. A floating IP costs €4.00 a month, billed per hour from allocation to release. The default quota is
5 per account.
Firewalls#
Every server has one stateful firewall, applied on the host in front of all its interfaces. Changes apply within seconds, also to running servers.
{
"enabled": true,
"default_inbound": "drop",
"default_outbound": "accept",
"rules": [
{ "direction": "inbound", "action": "accept", "protocol": "tcp", "port_start": 443, "port_end": 443, "comment": "https" },
{ "direction": "inbound", "action": "accept", "protocol": "tcp", "port_start": 22, "port_end": 22, "remote_cidr": "2001:db8:1234::/48", "comment": "ssh from the office" },
{ "direction": "inbound", "action": "accept", "protocol": "icmp" }
]
}
- Rules apply in order and the first match decides; otherwise the direction's default applies.
- Established and related traffic is always allowed, so replies to outbound connections come back.
protocolistcp,udp,icmpor empty for any. Ports needtcporudp;0means any port.remote_cidris an IPv4 or IPv6 address or CIDR, or empty for any.
Replace the whole firewall with PUT /v1/servers/{id}/firewall (or ankra-cloud firewall set <server-id> --file firewall.json); read it with GET /v1/servers/{id}/firewall.
Independently of your rules, every interface may only send from its own MAC and IP addresses (anti-spoofing), and ICMPv6 neighbour discovery and packet-too-big always pass. The metadata service is not affected by the firewall.